CVE-2026-33419Disclosure(minio / minio)

LOWCVSS 7.5 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch minio minio systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

MinIO is a high-performance object storage system. Prior to RELEASE.2026-03-17T21-25-16Z, MinIO AIStor's STS (Security Token Service) AssumeRoleWithLDAPIdentity endpoint is vulnerable to LDAP credential brute-forcing due to two combined weaknesses: (1) distinguishable error responses that enable username enumeration, and (2) absence of rate limiting on authentication attempts. An unauthenticated network attacker can enumerate valid LDAP usernames and then perform unlimited password guessing to obtain temporary AWS-style STS credentials, gaining access to the victim's S3 buckets and objects. This issue has been patched in RELEASE.2026-03-17T21-25-16Z.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-204CWE-307

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • minio

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-03-25); latest day: 2
  • 5 total mentions across 3 days

Affected systems

Vendors
Products
minio

Deep dive

Activity timeline5 mentions / 3d
01122Mentions · 2026-03-22: 1Mentions · 2026-03-25: 2Mentions · 2026-04-01: 2Patch / Workaround · 2026-03-22: 1Patch / Workaround · 2026-03-25: 1Technical Details · 2026-03-22: 1Technical Details · 2026-03-25: 2Technical Details · 2026-04-01: 103-2203-2504-01
Signal classification2 categories
Disclosure
480.0%
General
120.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-221
Disclosure1
2026-03-252
Disclosure2
2026-04-012
Disclosure1General1
Full discourse5 posts
  • ZAST AI@zast_ai
    Disclosure

    We verified CVE-2026-33419 in MinIO. The LDAP-backed STS flow exposed valid usernames, accepted repeated guesses, and returned temporary credentials on success. That turns one auth surface into a direct storage access problem. Project footprint: 60.5k+ GitHub stars. https://t.co/JfAjKV2K9J

    Post summary

    The tweet confirms the existence of CVE‑2026‑33419 in MinIO, detailing that the LDAP-backed STS flow improperly exposes usernames and hands out temporary credentials, constituting an authentication bypass.

    1000055
    33 followersView on X
  • CCB Alert@CCBalert
    Disclosure

    Warning: Critical #CVE-2026-33322 and #CVE-2026-33419 affect #MinIO and expose critical weaknesses in OIDC and LDAP authentication mechanisms. Attackers could forge identities or perform brute-force attacks. #Patch#Patch#Patch

    Post summary

    The post warns about two critical CVEs affecting MinIO’s OIDC and LDAP authentication, notes that attackers could forge identities or brute‑force access, and indicates that patches are available.

    01000201
    7.2K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-33419: MinIO: LDAP login brute-force vi... MinIO's STS endpoint leaks usernames through error responses then lets attackers brute-force LDAP creds with zero rate ... https://zerodaysignal.com/vulnerability/CVE-2026-33419 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post announces CVE‑2026‑33419, detailing how MinIO’s STS endpoint leaks usernames and enables LDAP brute‑force, but it does not provide a PoC, exploit code, active exploitation evidence, or patch information.

    0100076
    168 followersView on X
  • ZAST AI@zast_ai
    General

    This case is one example of a broader shift: defenders need verified execution paths, not just more suspicious signals. Try it on your codebase: https://zast.ai/ Technical report: https://blog.zast.ai/security%20research/CVE-2026-33419-Analysis/

    Post summary

    The post references a technical report on CVE-2026-33419 and a code analysis tool, but does not provide any PoC, exploit, active exploitation, patch, or detailed technical information.

    0000039
    33 followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    `MinIO` LDAP is vulnerable to brute-force and user enumeration (CVE-2026-33419) lacking rate limits. Risk of unauthorized access. Implement network-level rate limiting. #MinIO #infosec #cybersecurity https://www.pulsepatch.io/posts/cve-2026-33419-minio-ldap-brute-force-user-enumeration

    Post summary

    CVE‑2026‑33419 exposes a MinIO LDAP brute‑force and enumeration flaw caused by missing rate limits, and the advisory recommends applying network‑level rate limiting to mitigate unauthorized access.

    0000029
    2 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appminiominio---

Explore more